On Wed, Apr 3, 2019 at 10:53 AM <[email protected]> wrote: > > Hi > > I have setup my OSSEC server and the OSSEC agents are sending logs to it > successfully. The logs are being stored in the archives.log file with the > hostname and the IP address of the agent. However any alerts/log events > created by the OSSEC server itself do not contain the IP address - just the > hostname. I really need the server IP to be logged since the logs are being > forwarded to a SIEM. > > Does anyone know if this is possible? >
There is no setting for this that I'm aware of. > Thanks > Fiona > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
